previous (02): Examine the files sample_1.pcap, sample_2.pcap and sample_3.pcap using ethereal (...)

[03] Pay special attention to the file sample_2.pcap. As you can remember, the file contained suspiciously many packets listed as TCP (other). Have a look at a few of these packets (for example packets numbered 515 and 516, 517 and 518, 519 and 520 – timestamps starting at 126.925486).

Can you see where these packets came from?

(+) show hint

next (04): Can you see any other evidence of suspicious activity (...)
